EL Finans’ın hesap, şifreli kişisel bulut, ortak hesap, yapay zekâ, reklam ve tanılama özelliklerinde verileri nasıl işlediğini bu politika açıklar.
Hesapsız Kullanım ve Premium Hesabı
Gelir-gider kaydı, bütçe ve birikim gibi temel finans özellikleri EL Finans hesabı oluşturmadan cihazda kullanılabilir. Bu kullanımda bir EL Finans hesabı oluşturulmaz; hesap kimliği veya e-posta adresi istenmez.
Premium için hesapla giriş gerekir. Hesap; mağaza satın alma doğrulamasını, abonelik ve AI haklarını, şifreli bulut yedeklerini, ortak hesap yetkilerini ve cihazlar arası geri yüklemeyi doğru kullanıcıyla eşleştirmek için kullanılır. Ödeme kartı veya banka giriş bilgileriniz EL Finans tarafından saklanmaz.
Toplanan ve İşlenen Veriler
Kullandığınız özelliklere göre aşağıdaki veriler işlenebilir:
- Finansal kayıtlar: gelir, gider, borç, kategori, tutar, para birimi, tarih, hesap, bütçe, plan, hedef ve varlık bilgileri.
- Kullanıcı içeriği: işlem notları, açıklamalar, hesap adları ve girdiğiniz serbest metinler.
- Fotoğraf veya belgeler: fiş ya da belge tarama başlatıldığında seçilen içerik geçici olarak işlenir.
- Hesap ve üyelik bilgileri: kullanıcı kimliği, e-posta, görünen ad, giriş sağlayıcısı, sağlayıcı profil görseli, ortak hesap üyeliği, rolü, davet ve erişim kayıtları.
- Satın alma bilgileri: ürün, abonelik durumu, süre, işlem kimliği, doğrulama sonucu ve AI kredi hareketleri. Ödeme kartı bilgileri mağazalar tarafından işlenir.
- Teknik ve tanılama verileri: hata mesajı, stack trace, cihaz/işletim sistemi, uygulama sürümü ve hassas alanları maskelenmiş hata bağlamı.
- Reklam verileri: IP adresi, yaklaşık konum çıkarımı, reklam ve uygulama etkileşimi, tanılama bilgisi ve cihaz/uygulama tanımlayıcıları.
- Tercihler ve güvenlik ayarları: dil, tema, para birimi, bildirim, PIN/biyometri ve yedekleme tercihleri.
İşleme Amaçları
Veriler; uygulamanın temel finans özelliklerini sunmak, hesabı ve Premium haklarını yönetmek, satın almaları doğrulamak, isteğe bağlı bulut senkronizasyonu/yedekleme ve cihaz kurtarma sağlamak, ortak hesapları işletmek, kullanıcı tarafından başlatılan AI analizini üretmek, ücretsiz sürümde reklam göstermek, dolandırıcılığı ve kötüye kullanımı önlemek, hataları teşhis etmek, güvenliği ve hizmet sürekliliğini sağlamak amacıyla işlenir. Kişisel finans verileri satılmaz, kiralanmaz veya reklam hedeflemesinde kullanılmaz.
Verilerin Saklanması ve Güvenlik
Kişisel finans verileri cihazda AES-256-GCM ile şifreli olarak saklanır. Kişisel bulut senkronizasyonu ve yedekleme kullanıldığında finans verileri Supabase altyapısına cihazda şifrelenmiş veri olarak aktarılır. Açık şifreleme anahtarları sunucuya gönderilmez. Acil Kurtarma Kodu oluşturulursa bulut anahtarının yalnızca kurtarma koduyla cihazda açılabilen şifreli zarfı Supabase’de saklanır; kurtarma kodu ve açık anahtar sunucuya gönderilmez.
Yerel ve bulut .elfb yedekleri şifrelidir. Aktarım sırasında HTTPS/TLS kullanılır. Hassas sunucu anahtarları uygulama paketinde tutulmaz.
Bulut Senkronizasyonu, Yedekleme ve Kurtarma
Hesapla giriş yapan kullanıcı isteğe bağlı bulut senkronizasyonu, manuel veya zamanlanmış bulut yedeği kullanabilir. Planlı cihaz değişiminde Cihaz Aktarımı; eski cihaz kullanılamadığında daha önce kaydedilmiş Acil Kurtarma Kodu; alternatif olarak parola korumalı manuel .elfb yedeği kullanılabilir. Eski cihaz, kurtarma kodu ve manuel yedek birlikte kaybedilirse sıfır bilgi şifreleme modeli nedeniyle eski kişisel bulut verileri kurtarılamaz.
Cihaz Aktarımı paketi cihazda şifrelenir ve özel Supabase Storage alanında geçici tutulur. Aktarım oturumu 15 dakika içinde sona erer; tamamlanan, iptal edilen veya süresi dolan oturumların teknik metadata kayıtları güvenlik ve temizlik amacıyla sınırlı süre tutulur.
Ortak Hesaplar
Ortak hesaba eklenen işlem, tekrarlayan plan, borç, kategori ve güncelleme bilgileri yetkili üyeler tarafından görülebilmesi ve eşitlenebilmesi için Supabase’de şifrelenmemiş JSONB olarak tutulur. Bu, kişisel şifreli bulut yedeğinden ayrı ve açık bir istisnadır. Ortak hesap verileri herkese açık değildir; Supabase Row Level Security, hesap üyeliği ve sahip/yönetici rolleriyle korunur.
Bir ortak hesaba veri eklediğinizde bu verinin diğer yetkili üyelerce görülebileceğini kabul etmiş olursunuz. Hesap sahibi üyeleri yönetebilir ve ortak hesabı kalıcı olarak silebilir. Bir üyenin ayrılması, diğer üyelerin ortak hesapta tutmaya devam ettiği verileri otomatik olarak silmez.
Yapay Zekâ Özellikleri
AI özellikleri yalnızca kullanıcı ilgili analizi başlattığında ve ayrı açık rıza verdiğinde çalışır. İstekler kimliği doğrulanmış Supabase Edge Function üzerinden Google Gemini API’ye iletilir. Özelliğe göre şu içerikler gönderilebilir:
- Hızlı Kayıt: yazdığınız metin, kategori listesi, güncel tarih ve son 8 işlemin tür, tutar, para birimi, kategori ve not bilgisi.
- Fiş/belge tarama: seçtiğiniz görsel veya belge, girdiğiniz ipucu ve kategori listesi.
- Finansal Danışman: toplam ve aylık gelir-gider özetleri, öne çıkan kategoriler, aktif planlar, birikim hedefleri ve varlık başlık/tutarları.
- Tasarruf Avcısı: dönem özetleri; kısa dönemlerde kategori, tutar ve işlem notlarını içeren gider listesi.
AI içeriği reklam amacıyla kullanılmaz. Production hizmeti, gönderilen prompt ve yanıtların Google tarafından ürün/model geliştirme amacıyla kullanılmadığı billing etkin Gemini API veri işleme koşullarıyla çalıştırılmalıdır. Google sınırlı süreli güvenlik/kötüye kullanım kayıtları tutabilir. AI özellikleri 18 yaş ve üzeri kullanıcılar içindir; rıza Ayarlar’dan geri alınabilir.
Uygulama İçi Satın Almalar
Premium abonelikler ve AI kredi paketleri Apple App Store veya Google Play üzerinden işlenir. Satın alma makbuzu veya tokenı sunucu tarafında ilgili mağazayla doğrulanır; ürün, işlem kimliği, doğrulama sonucu ve hak bilgisi EL Finans hesabına bağlanır. Ödeme kartı veya banka bilgileri EL Finans tarafından alınmaz ya da saklanmaz.
Reklamlar ve Gizlilik Tercihleri
Ücretsiz sürüm banner veya ödüllü reklam gösterebilir. Google AdMob SDK; reklam sunumu, ölçüm, güvenlik ve sahteciliği önleme amacıyla IP adresi, IP’den çıkarılabilen yaklaşık konum, reklam/uygulama etkileşimleri, SDK tanılama bilgileri ve cihaz ya da uygulama tanımlayıcılarını otomatik işleyebilir. EL Finans reklam isteklerini kişiselleştirilmemiş reklam olarak işaretler ve finansal kayıt, e-posta, kullanıcı notu veya satın alma geçmişini reklam hedeflemesi için AdMob’a göndermez.
Bölgesel mevzuat gerektirdiğinde Google User Messaging Platform üzerinden izin veya gizlilik tercihi alınır. Uygun bölgelerde kullanıcı bu tercihlere Ayarlar → Gizlilik ve Yasal Bilgiler bölümünden yeniden ulaşabilir.
Hata ve Çökme Raporları
Production sürümünde uygulama kararlılığını izlemek ve hataları düzeltmek için Sentry kullanılır. Sentry’ye hata mesajı, stack trace, cihaz/işletim sistemi, uygulama sürümü ve teknik bağlam gönderilebilir. Gönderim öncesinde finansal tutarlar, e-posta, token, yetkilendirme başlıkları ve bilinen hassas alanlar maskelenir. Sentry kullanıcı davranışı profili oluşturmak veya reklam hedeflemek için kullanılmaz.
Üçüncü Taraf Hizmetler
Uygulama şu hizmetlerle çalışabilir:
- Supabase: kimlik doğrulama, veri senkronizasyonu, yedekleme, Storage, veritabanı ve sunucu fonksiyonları.
- Google ve Apple ile Giriş: kullanıcı tarafından seçildiğinde kimlik doğrulama.
- Google Gemini API: kullanıcı tarafından başlatılan ve ayrı rızaya bağlı AI analizi.
- Apple App Store ve Google Play: satın alma, abonelik ve doğrulama.
- Google AdMob ve User Messaging Platform: reklam sunumu ve gizlilik tercihleri.
- Sentry: hassas alanları maskelenmiş hata ve çökme tanılaması.
- Truncgil ve Binance: piyasa verileri Supabase sunucusu üzerinden alınır; bu sağlayıcılara kullanıcı IP’si veya finansal kaydı gönderilmez.
Saklama ve Silme
Cihazdaki veriler kullanıcı silene veya uygulama verileri kaldırılana kadar tutulur. Kişisel bulut senkronizasyonu, yedekler, hesap profili ve kurtarma zarfı kullanıcı ilgili veriyi ya da hesabını silene kadar; satın alma ve güvenlik kayıtları sözleşme, mağaza doğrulaması, sahteciliği önleme ve yasal yükümlülüklerin gerektirdiği süre boyunca tutulabilir. Ortak hesap verileri ortak hesap sahibi silene kadar diğer yetkili üyeler için kalabilir. Cihaz aktarım paketleri kısa ömürlüdür; teknik oturum kayıtları sınırlı süre sonra temizlenir. Sentry, AdMob, mağazalar ve Gemini tarafından tutulan veriler ilgili sağlayıcının geçerli saklama kurallarına tabidir.
Hesap silme işlemi ilgili Supabase hesap verilerini ve kullanıcıya ait özel Storage yedeklerini siler; cihazdaki bulut anahtarı da kaldırılır. Kimlikten bağımsız veya yasal olarak saklanması gereken sınırlı güvenlik/satın alma kayıtları ilgili saklama süresinin sonuna kadar tutulabilir.
Kullanıcı Hakları
Kullanıcı uygulama içinden yerel verilerini silebilir, bulut verilerini sıfırlayabilir, AI rızasını geri alabilir veya hesabını silebilir. Ayrıca support@elfinans.com üzerinden erişim, düzeltme, silme, taşıma, kısıtlama veya itiraz talebinde bulunabilir.
- AB/AEA kullanıcıları GDPR kapsamındaki haklarını kullanabilir.
- ABD/Kaliforniya kullanıcıları yürürlükteki eyalet gizlilik haklarını kullanabilir.
- Türkiye’deki kullanıcılar KVKK kapsamındaki hakları için uygulama içindeki Aydınlatma Metni’ne başvurabilir.
- Brezilya’daki kullanıcılar LGPD kapsamında işleme teyidi, erişim, düzeltme, anonimleştirme, engelleme veya silme, taşınabilirlik, verilerin paylaşıldığı kuruluşlar hakkında bilgi, rızayı geri alma ve ANPD’ye başvuru haklarını kullanabilir. Supabase, Google, Apple ve Sentry gibi hizmet sağlayıcılarının sistemleri Brezilya dışında bulunabilir; uluslararası aktarımlar LGPD’nin uygulanabilir koşulları ve güvenceleriyle sınırlandırılır.
Yaş Sınırı ve Çocukların Gizliliği
EL Finans çocuklara yönelik değildir. Hesap, Premium ve AI özellikleri 18 yaş ve üzeri kullanıcılar içindir. 18 yaşın altındaki kullanıcılar AI özelliklerini kullanmamalı veya AI hizmetine içerik göndermemelidir. 18 yaş altı bir kişiye ait verinin yanlışlıkla işlendiğini düşünüyorsanız silme talebi için support@elfinans.com adresine başvurabilirsiniz.
Politika Değişiklikleri
Veri işleme yöntemleri veya üçüncü taraf hizmetler değiştiğinde bu politika güncellenir. Güncel sürüm uygulamada ve elfinans.com adresinde yayımlanır. Önemli değişikliklerde yasal metin sürümü artırılarak uygulama içinde yeniden bilgilendirme ve gerektiğinde yeni onay ya da rıza alınır.
İletişim
Gizlilik politikası, veri talepleri veya şikâyetler için:
Veri sorumlusu: Emre Yaldız
E-posta: support@elfinans.com
Web: https://elfinans.com
This policy explains how EL Finans processes data across account, encrypted personal cloud, shared-account, AI, advertising and diagnostics features.
Use Without an Account and the Premium Account
Basic income/expense, budget and savings features can be used locally without creating an EL Finans account. In this mode no EL Finans account is created and no account ID or email is requested.
Premium requires sign-in. The account associates store verification, subscription and AI entitlements, encrypted cloud backups, shared-account permissions and cross-device recovery with the correct user. EL Finans does not store payment-card details or online-banking credentials.
Data We Collect and Process
Depending on the features you use, the app may process:
- Financial records: income, expenses, debts, categories, amounts, currencies, dates, accounts, budgets, plans, goals and asset information.
- User content: transaction notes, descriptions, account names and free text you enter.
- Photos or documents: content selected for receipt/document scanning is processed temporarily.
- Account and membership information: user ID, email, display name, sign-in provider, provider profile image, shared-account membership, role, invitation and access records.
- Purchase information: product, subscription status and duration, transaction ID, verification result and AI-credit activity. Payment details are processed by the stores.
- Technical and diagnostic data: error message, stack trace, device/OS, app version and error context with sensitive fields scrubbed.
- Advertising data: IP address, approximate location inferred from IP, ad/app interactions, diagnostics and device/app identifiers.
- Preferences and security settings: language, theme, currency, notifications, PIN/biometrics and backup preferences.
Purposes of Processing
Data is processed to provide core finance features; manage accounts, Premium and purchases; provide optional cloud sync, backup and recovery; operate shared accounts; generate user-initiated AI analysis; show ads in the free version; prevent fraud and abuse; diagnose errors; and maintain security and service continuity. Personal financial data is not sold, rented or used for ad targeting.
Storage and Security
Personal financial data is stored on-device using AES-256-GCM encryption. When personal cloud sync or backup is used, data is encrypted on-device before transfer to Supabase. Plaintext keys are not sent to the server. If an Emergency Recovery Code is created, Supabase stores only an encrypted envelope of the cloud key; the recovery code and plaintext key are not sent to the server.
Local and cloud .elfb backups are encrypted, transfers use HTTPS/TLS, and sensitive server credentials are not stored in the app package.
Cloud Sync, Backup and Recovery
Signed-in users may enable cloud sync and manual or scheduled cloud backup. Device Transfer can be used for a planned move; a previously saved Emergency Recovery Code can be used when the old device is unavailable; or a password-protected manual .elfb backup can be restored. If the old device, recovery code and manual backup are all lost, old personal cloud data cannot be recovered under the zero-knowledge design.
A Device Transfer package is encrypted on-device and kept temporarily in private Supabase Storage. The session expires after 15 minutes; limited technical metadata for completed, cancelled or expired sessions is retained briefly for security and cleanup.
Shared Accounts
Transactions, recurring plans, debts, categories and update information added to a shared account are stored as unencrypted JSONB in Supabase so authorized members can view and synchronize them. This is an explicit exception separate from encrypted personal cloud backups. Shared data is not public; it is protected by Supabase Row Level Security, membership and owner/admin roles.
By adding data to a shared account you acknowledge that other authorized members can view it. The owner can manage members and permanently delete the shared account. A member leaving does not automatically delete data that remaining members continue to keep in the shared account.
AI Features
AI runs only when the user starts the feature and gives separate explicit consent. Requests pass through an authenticated Supabase Edge Function to the Google Gemini API. Depending on the feature, the following may be sent:
- Quick Entry: your text, category list, current date and the type, amount, currency, category and note of the latest 8 transactions.
- Receipt/document scan: selected image or document, optional hint and categories.
- Financial Advisor: income/expense totals and monthly summaries, top categories, active plans, savings goals and asset titles/amounts.
- Savings Hunter: period summaries and, for short periods, expense categories, amounts and notes.
AI content is not used for advertising by EL Finans. Production must use a billing-enabled Gemini configuration under which prompts and responses are not used by Google for product/model improvement. Google may retain limited security/abuse logs. AI features are for users aged 18 or older and consent can be withdrawn in Settings.
In-App Purchases
Premium subscriptions and AI-credit packages are processed through the Apple App Store or Google Play. A receipt or token is verified server-side with the relevant store, and the product, transaction ID, verification result and entitlement are associated with the EL Finans account. EL Finans does not receive or store payment-card or bank details.
Advertising and Privacy Choices
The free version may show banner or rewarded ads. Google Mobile Ads SDK may automatically process IP address, approximate location inferred from IP, ad/app interactions, SDK diagnostics and device/app identifiers for ad delivery, measurement, security and fraud prevention. EL Finans marks ad requests as non-personalized and does not send financial records, email, user notes or purchase history to AdMob for targeting.
Where regional law requires it, consent or privacy choices are collected through Google User Messaging Platform. Eligible users can revisit these choices under Settings → Privacy and Legal Information.
Error and Crash Reports
Production releases use Sentry to monitor stability and fix errors. Error messages, stack traces, device/OS, app version and technical context may be sent. Before transmission, financial amounts, email addresses, tokens, authorization headers and known sensitive fields are scrubbed. Sentry is not used to create behavioral advertising profiles.
Third-Party Services
The app may use:
- Supabase for authentication, database, sync, backup, Storage and server functions.
- Google and Sign in with Apple when selected for authentication.
- Google Gemini API for user-initiated AI analysis subject to separate consent.
- Apple App Store and Google Play for purchases, subscriptions and verification.
- Google AdMob and User Messaging Platform for ads and privacy choices.
- Sentry for error/crash diagnostics with sensitive fields scrubbed.
- Truncgil and Binance for market data fetched by the Supabase server; these providers do not receive the user IP or financial records.
Retention and Deletion
On-device data remains until the user deletes it or removes app data. Personal cloud sync, backups, profile and recovery envelope remain until the relevant data or account is deleted. Purchase and security records may be retained as required for contracts, store verification, fraud prevention and legal obligations. Shared-account data may remain for authorized members until the owner deletes the shared account. Transfer packages are short-lived and technical session records are cleaned after a limited period. Data retained by Sentry, AdMob, stores and Gemini is subject to each provider’s current retention rules.
Account deletion removes the related Supabase account data and private Storage backups and deletes the cloud key from the device. Limited de-identified or legally required security/purchase records may remain until the applicable retention period ends.
User Rights
Users can delete local data, reset cloud data, withdraw AI consent or delete the account in the app. Requests for access, correction, deletion, portability, restriction or objection can also be sent to support@elfinans.com.
- EEA users may exercise GDPR rights.
- US/California users may exercise applicable state privacy rights.
- Users in Türkiye can consult the in-app KVKK Notice for their rights under the KVKK.
- Users in Brazil may exercise LGPD rights to confirmation of processing, access, correction, anonymization, blocking or deletion, portability, information about data sharing, withdrawal of consent and petitions to the ANPD. Systems of service providers such as Supabase, Google, Apple and Sentry may be located outside Brazil; international transfers are limited by applicable LGPD conditions and safeguards.
Age Limit and Children’s Privacy
EL Finans is not directed to children. Account, Premium and AI features are intended for users aged 18 or older. Users under 18 must not use AI features or send content to the AI service. If you believe data relating to a person under 18 was processed by mistake, contact support@elfinans.com to request deletion.
Policy Changes
This policy is updated when processing practices or third-party services change. The current version is published in the app and at elfinans.com. For significant changes, the legal-document version is increased and users are informed again; new acceptance or consent is requested where required.
Contact
For privacy questions, data requests or complaints:
Data controller: Emre Yaldız
Email: support@elfinans.com
Web: https://elfinans.com
Esta política explica como o EL Finans trata dados nos recursos de conta, nuvem pessoal criptografada, conta compartilhada, inteligência artificial, publicidade e diagnóstico.
Uso sem conta e conta Premium
As funções básicas de receitas, despesas, orçamento e poupança podem ser usadas localmente sem criar uma conta EL Finans; não é pedido ID nem e-mail.
O Premium exige login. A conta associa ao usuário correto a validação de compras, direitos de assinatura e IA, backups na nuvem criptografados, permissões de contas compartilhadas e recuperação entre dispositivos. O EL Finans não armazena cartões nem credenciais bancárias.
Dados coletados e tratados
Conforme as funções, podem ser tratados:
- Dados financeiros: receitas, despesas, dívidas, categorias, valores, moedas, datas, contas, orçamentos, planos, objetivos e ativos.
- Conteúdo: notas, descrições, nomes de contas e texto livre.
- Fotos/documentos: conteúdo escolhido para digitalização, tratado temporariamente.
- Conta/membro: ID, e-mail, nome, fornecedor de acesso, imagem, membro, função, convites e acessos compartilhados.
- Compras: produto, estado/duração, ID de transação, validação e movimentos de créditos IA; a loja trata o pagamento.
- Técnica/diagnóstico: erro, stack trace, dispositivo/SO, versão e contexto depurado.
- Publicidade: IP, localização aproximada inferida, interações, diagnósticos e identificadores.
- Preferências/segurança: idioma, tema, moeda, notificações, PIN/biometria e backups.
Finalidades do tratamento
Os dados servem para fornecer funções financeiras; gerenciar conta, Premium e compras; oferecer sincronização, backup e recuperação na nuvem opcionais; operar contas compartilhadas; gerar análises de IA iniciadas pelo usuário; mostrar anúncios na versão gratuita; evitar fraude e abuso; diagnosticar erros e assegurar segurança e continuidade. Os dados financeiros pessoais não são vendidos, alugados nem usados para segmentação publicitária.
Armazenamento e segurança
Os dados financeiros pessoais são criptografados no dispositivo com AES-256-GCM. Na sincronização ou backup na nuvem pessoal, são criptografados antes do envio para a Supabase; as chaves em texto simples não vão para o servidor. Se for criado um Código de recuperação de emergência, a Supabase armazena apenas um envelope criptografado da chave da nuvem; nem o código nem a chave simples saem do dispositivo.
Os backups .elfb locais e na nuvem são criptografados, as transferências usam HTTPS/TLS e os segredos do servidor não integram o aplicativo.
Sincronização, backup e recuperação na nuvem
O usuário autenticado pode ativar sincronização e backups manuais ou agendados. Para mudança planejada usa-se Transferência de dispositivo; se o antigo estiver indisponível, um Código de recuperação de emergência armazenado; em alternativa, um backup .elfb manual com senha. Se dispositivo, código e backup forem todos perdidos, os dados na nuvem pessoais antigos não podem ser recuperados devido ao modelo de conhecimento zero.
O pacote de transferência é criptografado no dispositivo e armazenado temporariamente em Supabase Storage privado. A sessão expira em 15 minutos; metadados técnicos limitados são mantidos brevemente para segurança e limpeza.
Contas compartilhadas
Transações, planos recorrentes, dívidas, categorias e atualizações são armazenados na Supabase como JSONB não criptografado para que membros autorizados os consultem e sincronizem. É uma exceção expressa, separada dos backups pessoais criptografados. Não são públicos: estão protegidos por Row Level Security, adesão e funções de proprietário/administrador.
Ao adicionar dados aceita a sua visibilidade por membros autorizados. O proprietário gerencia membros e pode excluir definitivamente a conta. A saída de um membro não apaga automaticamente dados mantidos pelos demais.
Funções de inteligência artificial
A IA só funciona quando o usuário inicia a função e dá consentimento explícito separado. Os pedidos passam por uma Supabase Edge Function autenticada para o Google Gemini API. Podem ser enviados:
- Registro rápido: texto, categorias, data e tipo, valor, moeda, categoria e nota das últimas 8 transações.
- Digitalização: imagem/documento, indicação opcional e categorias.
- Consultor financeiro: totais e resumos mensais, categorias principais, planos, objetivos e títulos/valores de ativos.
- Caçador de poupança: resumos e, em períodos curtos, categorias, valores e notas.
O EL Finans não usa este conteúdo para publicidade. A produção deve usar Gemini com faturamento ativo, sem uso de prompts/respostas pelo Google para melhorar produtos/modelos. O Google pode manter registros limitados de segurança/abuso. IA para maiores de 18; consentimento revogável nas Configurações.
Compras no aplicativo
Assinaturas Premium e pacotes de créditos IA são processados pela Apple App Store ou Google Play. Recibo ou token são validados no servidor com a loja; produto, ID, resultado e direitos ligam-se à conta EL Finans. O EL Finans não recebe nem armazena dados de cartão ou banco.
Publicidade e opções de privacidade
A versão gratuita pode mostrar banners ou anúncios premiados. Google Mobile Ads SDK pode tratar automaticamente IP, localização aproximada inferida, interações, diagnósticos e identificadores para entrega, medição, segurança e fraude. O EL Finans pede anúncios não personalizados e não envia registros financeiros, e-mail, notas ou histórico de compras ao AdMob para segmentação.
Quando a lei regional exige, consentimento ou opções são coletados pelo Google User Messaging Platform e podem ser revistos em Configurações → Privacidade e informações legais.
Relatórios de erros e falhas
A produção usa Sentry para monitorar estabilidade e corrigir erros. Podem ser enviados mensagem, stack trace, dispositivo/SO, versão e contexto técnico. Antes são ocultados valores financeiros, e-mails, tokens, cabeçalhos de autorização e campos sensíveis conhecidos. Sentry não cria perfis publicitários.
Serviços de terceiros
O aplicativo pode usar:
- Supabase: autenticação, base de dados, sincronização, backups, Storage e funções.
- Acesso Google/Apple: quando escolhido.
- Google Gemini API: análise iniciada pelo usuário com consentimento.
- Apple App Store/Google Play: compras, assinaturas e validação.
- Google AdMob/User Messaging Platform: anúncios e privacidade.
- Sentry: diagnóstico depurado.
- Truncgil/Binance: dados de mercado obtidos pelo servidor Supabase; não recebem IP nem dados financeiros do usuário.
Conservação e exclusão
Os dados do dispositivo permanecem até serem apagados pelo usuário ou com os dados do app. Sincronização e backups pessoais, perfil e envelope de recuperação ficam até excluir dados ou conta. Registros de compra/segurança podem ser armazenados por contrato, validação, fraude e lei. Dados compartilhados podem ficar até o proprietário apagar a conta. Pacotes de transferência são breves; registros técnicos são limpos depois. Dados na Sentry, AdMob, lojas e Gemini seguem as suas regras atuais.
Excluir a conta apaga dados Supabase associados, backups privados e a chave da nuvem do dispositivo. Registros limitados anonimizados ou legalmente exigidos podem permanecer até o fim do prazo.
Direitos do usuário
Na app pode apagar dados locais, restaurar dados da nuvem, retirar consentimento IA ou excluir a conta. Pedidos de acesso, retificação, exclusão, portabilidade, limitação ou oposição: support@elfinans.com.
- Usuários do EEE têm direitos RGPD.
- Usuários dos EUA/Califórnia têm direitos estaduais aplicáveis.
- Usuários de Turquia consultam o aviso KVKK no app.
- Usuários no Brasil podem exercer, nos termos da LGPD, os direitos de confirmação do tratamento, acesso, retificação, anonimização, bloqueio ou exclusão, portabilidade, informação sobre compartilhamentos, revogação do consentimento e petição perante a ANPD. Os sistemas de prestadores como Supabase, Google, Apple e Sentry podem estar fora do Brasil; as transferências internacionais são limitadas às hipóteses e garantias aplicáveis da LGPD.
Limite de idade e privacidade infantil
O EL Finans não se destina a crianças. Conta, Premium e IA são para maiores de 18. Menores não devem usar IA nem enviar conteúdo. Se dados de menor foram tratados por engano, peça exclusão em support@elfinans.com.
Alterações à política
A política é atualizada quando mudam os tratamentos ou terceiros. A versão atual está no app e em elfinans.com. Alterações importantes aumentam a versão legal, geram nova informação e, quando necessário, nova aceitação ou consentimento.
Contato
Para privacidade, pedidos ou reclamações:
Responsável pelo tratamento: Emre Yaldız
E-mail: support@elfinans.com
Web: https://elfinans.com